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CODES AND CIPHERS (Cryptology), general terms 
<l«» signatin g the methods or the parai^emalia employed in secret 
communications or involved in the science of cryptology (from 
Gr. kryptos, “Udden,” and logos, “word”). Because of the growth 
of governments, the expansion of commerce and especially the 
remarkable progress made in communications-electronics tech> 
nology, cryptology has come to play a very important role in 
governmental communications, especially diplomatic and military. 

It also plays a minor role in commercial, industrial and banking 
communications. Among the more tmcommon uses of cryptology 
are those in connection with attempts to establish authorship in 
cases where that has been brought into question, as, for example, 
that of the Shakespeare plays. 

In its early stages cryptology was concerned almost exclusively 
with secrecy in written communications and this article will be 
restricted very largely thereto, but the science has devcloj^ 
to the stage where it deals not only with enciphered writing 
(cryptograms) but also with other mediums of cryptocommuni- 
cation, such as enciphered telephony (didiony) and encijAered 
facsimile (cifax) tranunissions. 

Ciyptok^ onbraces the twin or comfdcmentaiy sciences of 
signal security and sigiud intelligence. The former deals with 
all the means and methods of protecting one’s own sigiuds against 
interception and reading or utilisation by unauthorised persons 
generally referred to as “the enemy.” The latter deals with all 
the means and methods emi^oyed in acquiring information or* 
intelligence by intercepting and solving the enemy’s crypto- 
signals or nullifying h^ signal security so that the signals or 
information derived from them can be used against him. 

Signal Security. — ^The principal components of this phase of 
cryptology are; (r) physical and personnel security; (j) trans- 
mission security; and (3) cryptosecurity. The first deals with 
the precautions and measures taken to assure that the physical 
arrangements and the facilities or procedures for safeguarding the 
paraphernalia or cryptomatetials used, i.e., the codes, ciphers, 
key lists, etc., are adequate for the purpose and that the personnel 
employed in operating the codes and ciphers or cipher machines 
are trustworthy. The second component deals with the means, 
methods and procedures for assuring that no information is in- 
advertently disclosed either by indiscretions of operators or by 
faults in the transmitting or receiving apparatus wUch may assist 
in the solution of the transmissions. The third component, crypto- 
security, which deals with the technical adequacy of the crypto- 
systems employed, is usually of greater interest and deserves 
more extensive treatment t^ the other two. In an article 
of this neture it is p ess ib ie o nl y to ^eaHniefly wtdi cr yp t og ra p hy 
(from Gr. hrypt^t, “ hidd e H ,” end grnpkem, “to write”), it b^ 
ing understo^ that many of the cryptoprinciples employed 
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for the protection of written communications, or signals rep- 
resenting thein,,can also be used in protecting or disgui^g other 
types of cryptosignalling; e.g., cifdiony and cifax. Cryptography 
deals with the processes, methods or means involved in 
preparing cryptograms, that is, messages or writings which are 
intended to be incomprehensible except to those who legitimately 
possess the proper special paraphenulia and the keys for those 
cryptograms.and know how to use them in order to reproduce the 
original plain text of the messages. These processes are ^isqally 
accomplished by means of cryptosystems employing c<^es or 
ciphers. The process of converting a plain-text message into a 
cryptogram is cidled enciphering (or encoding); that of recon- 
verting the cryptogram back into its intelligible form, when done 
by a legitimate or authorized conununicator, i.e., one who legiti- 
mately holds the para]diemalia and the key, is c^ed deciidiering 
(or deco<£ng). 

Although in theory no sharp line of denurcadon can be drawn 
between code systems and cipher syste^, in modem practice the 
technical differences between them are sufficiendy tiuitked to war- 
rant their being treated as separate categories of methods. Some 
authors include as a third and separate category the extensive but 
much less important one containing the so-called “concealment 
systems,” which are sometimes employed to hide an internal or 
secret message within an external or apparenUy iimocent piece 
of writing with a view to avoiding arousing suspicion in the minds 
of persons not privy to the secret, or to eluding censorship in 
wartime. In such systems the niessage or its elements are 
hidden or disguised by any one of hundreds of different means 
and methods, including such mediums as secret or invisible inks, 
microscopic writing, etc., but none of these concealment systems 
or devices will even be mendoned again herein. It is convenient 
to consider cipher systems first, then code systems, with the under- 
standing that only a very few of the limited number of systems 
suitable for serious usage can here be outlined. 

Cipher Systenu. — ^In general, ci{^r systems involve a crypto- 
graphic treatment of textual units of constant and equal len^, 
usuidly single letters, sometimes pairs, rarely sets of three letters, 
these textual units being treated as symbols without reference to 
their identides as component parts of words, phrases and sen- 
tences. Every pra^cal cipher system must comhitw (i) a. set 
of rules, processes or steps constituting the basic cryptogriqrhic 
method of treatment or procedure, called the general syston, 
which is agreed upon in advance by the communicators and which 
is constant in character, with (2) a specific key which is variable 
in character. In encif^ring plain text, the specific key, which 
may consist of a number or a series of numbers or a word, phrase, 
sentence, etc., controls the steps under the general system and 
determiiies the specific nature or exact composition of the ci{^ 
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message produced; in decipherment the specific key similarly 
controls the steps and determines what the deciphered text 
will be. When all operations are performed correctly, the two 
plain texts (before and after the cryptography) should be identi- 
cal or nearly so, save for minor differences arising from errors in 
their encipherment and transmission or in their reception and 
decipherment. The general system should be such that even if 
it is known to the enemy no properly enciphered message can be 
read by him unless he also knows the specific key or keys ap- 
plicable to that message. 

Despite a great diversity in the external appearance and in- 
ternal constitution of ciphers, there are only two basic classes 
of systems — transposition and substitution. (Concealment ci- 
phers are excluded from the discussion.) A transposition cipher 
involves a rearrangement or change in the sequence of the letters 
of the plain-text message without any change in their identity; a 
substitution cipher involves a replacement of the plain-text let- 
ters by other letters (or by other symbols) without any change in 
their sequence. The two systems may be combined in a single 
cryptosystem. 

The majority of transposition systems involve inscribing the 
letters of the plain text in a geometrical design called a matrix, 
beginning at a prearranged initial point and following a prescribed 
route, and then transcribing the letters from the matrix, beginning 
at another prearranged initial point and following another pre- 
scribed route. The matrix may take the form of a rectangle, 
trapezoid, octagon, triangle, etc., but systems in which the specific 
keys consist solely in keeping the matrices, the initial points and 
the routes secret are not often now employed because of their 
limited variability and, therefore, their relatively low degree of 
security. In this same class also fall systems which employ per- 
forated cardboard matrices called grilles, descriptions of wUch 
will be found in most of the older books on cryptography. The 
transposition system most commonly used in practice is that des- 




Flg. I. — An example of limple oolumnar tranepoeitidn. The numerical key 
la derived by numbering the letten of the keyword ("telegraph") in accord- 
ance with their relative order of appearance In the ordinary alphabet, repeated 
lettera, if preaent in the key. being numbered in aequence from left to right. 
The meamge ia written in the normal manner from left to right in aucceaaive 
horixontal linet underneath the key, forming a "rectangle of oolumna of 
lettera. Theae lettera are then tian^bed in regular groupa of five from the 
rectangle by reading doam the columna, taking the latter in the aequence 
indicated Iw the key numbera. The laat line of the rectangle may be completely 
filled with letten, nonaignlficanta being added U neoeaaaiy; but the aecurlty of 
the method ia conaiderably Increaaed if the laat line ahoara one or more blank 
apacea, aa in thia example. 



ignated as columnar transposition, wherein the transposition ma- 
trix takes the form of a simple rectangular figure the dimensions 
of which are determined in each instance jointly by the length of 
the individual message and the length of the specific key. An ex- 
ample is shown in fig. i. 

In the foregoing case the letters undergo a single transposition; 
in cases involving double transposition, that is, wherein the letters 
undergo two successive transpositions, the security of the ci^qito- 
grams is very greatly increased, provided the methods selected are 
such as will effectively disarrange individual letters and not merely 
whole columns or rows. A practical system of double transposi- 
tion is illustrated in fig. 2. The principal advantages of trans- 
position systems lie in their comparative simplicity, speed of 
operation and, in some cases, their high degree of security; but 
despite these important considerations they do not at the present 
time play a prominent role in practical cryptography. 

Substitution systems involve the use of conventional or cipher 
alfffiabets composed of two juxtaposed sequences, one (either 
expressed or implied) corresponding to the letters of the ordinary 
alphabet (a,b,c... x, y, s), the other containing their respective 
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(b) 



Crypiotram 

TARNC UDEEI LTTPO RNUEY URAIO FETER LH 



Fig. a. — An example of true double transposition. The cipher letters re- 
sulting from the first transposition rectangle (a) are written under the key 
of the second transposition rectangle (b) just as though they constituted plain- 
text, that is, from left to right, in successive horizontal rows. The hnal trans- 
position is then performed in exactly the same manner as in fig. i, yielding 
five-letter groups. The two rectangles may be based upon the same keyword, 
as in this example, or upon wholly different keywords. 



cipher equivalents. The complexity of a substitution system 
usually depends upon three factors: (i) the specific composition 
of the cipher alphabet or alphabets employed; (2) the number of 
them involved in a single cryptogram; and (3) the specific manner 
in which they are used. As to their composition, cipher alphabets 
are of various types and are known under various names, such as 
standard, direct, reversed, systematically mixed, key-word mixed, 
random mixed, reciprocal, etc., all having reference to the nature* 
of the two sequences composing them, the interrelations existing 
among them internally or externally, etc. The most important 
factor in connection with a cipher alphabet is whether its two 
sequences, regardless of their composition, are known or unknown 
to the enemy; for, if known, any conventional or disarranged al- 
phabet may be handled with the same facility as the normal alpha- 
bet. As to the number of alphabets involved in it, a cryptogram 
is either monoalphabetic, involving a single cipher alphabet, or 
polyalphabetic, involving two or more alphabets. In essence the 
difference between the two types lies in the fact that in the former 
the equivalence between plain-text and cipher letters is invariant, 
i.e., the equivalence is of a constant or invariable nature through- 
out the cryptogram, whereas in the latter it is of a changing or 
variable nature, controlled by the key. With regard to secrecy, the 
third condition mentioned above, namely, the specific manner in 
which the various cipher alphabets are employed, is the most im- 
portant in determining the degree of security or resistance the 
cryptogram will have against cryptanalysis, as explained below. 

Monoalphabetic substitution is usually uniliteral; i.e., each let- 
ter of the plain text is replaced by a single character. Cases of 
biliteral, triliteral, etc., substitution are sometimes encountered; 
an example using biliteral equivalents is shown in fig. 3. No mat- 
ter how many characters are in the groups composing the cipher 
equivalents for plain-text letters, if the groups are always the 
same for each letter, the substitution system is still monoalpha- 
betic and the cipher can be treated as such. 

Polyalphabetic systems are often referred to as double-key sys- 
tems and, as noted above, employ two or more cipher alphabets 
in the encipherment of single dispatches. In a given system the 



Flain-text menage: DELAY DEPARTUaE UNTIL FURTHER NOTICE. 
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Second letter Endphering 

Plain: DELAVDEPART 

Cipher: CA AB AC BA ED CA AB BB BA AE AA 

Plain: U REUNTI LFU R 

Cipher: DE AE AB DE DA AA CC AC CB DE AE 

Plain: THERNOTICE 

Cipher: AABCABAEDADBAACCBEAB 

Cryfleiram 

CAABA CBAEO CAABB BBAAE att. 

Fig. 3- — An example of biliteral, monoalphabetic substitution. A keyword 
alphabet of 25 letten (I serving also for I) is written in a square 5x5. Hn thia 
case the alphabet is based upon the word "telegraph.) ” The letten (A,B,C,D, 
E) at the side and top of the square, taken in ^n, can then be used to repre- 
sent the letten within the square. Thus. O =CA, E - AB, etc. The letten at 
the side of the square may be the same as or different from those at the Um; 
in both casn keywords, identical or different, may be uaed instead of the 
letten A.B.C.D,& 
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cipher alphabets may be entirely independent or they may be 
interrelated. In the simplest case of interrelated alphabets, that 
resulting from juxtaposing, at all points of coincidence, two pri- 
mary sequences which are normal sequences proceeding in the 
same direction (a, b,c . . . x, y, z), the secondary cipher alphabets 
are called standard alphabets; these when successively tabulated 
yield a symmetrical or square table (fig. 4) which is generally 
referred to in the literature as a Vigen^re table, a quadricular 
table, etc. 

Such a table may be used in several ways. The most common 
method employs the top row of letters as the plain-text sequence 
and the successive horizontal rows as the cipher sequences, each 
of which may be designated by its initial letter. Thus, the fourth 
or D alp>habet is the one in which plain text A is represented by 
cipher D; i.e., Af=D^, etc. In the ninth or I alphabet, 

A^=I„ = etc. Therefore, when several such alphabets are 

to be employed, the letters of a key word can serve to indicate the 
number, identity and sequence of the cipher alphabets to be used 
consecutively in the cryptographic opierations. 

This typie of cryptogram is usually referred to as the Vigenere 
cipher or as le chijre indAchifrable, although Blaise de Vigenire 
never claimed that he invented the table or the system; he was 
merely among the first to describe it {see below). 



Plain-text letter 

ABCDEFQH I JKLMNOPQRSTUVWXYZ 

"i 

A 
B 
C 
D 
E 
F 



A B C 0 E F 
B C D E F Q 
C O E F O H 
0 E F O H I 
E F O H I J 
F O H I J K 
OH I J K L 
H I J K LM 
I J K LM N 
J K LM N 0 
K LM N O P 
LM N O P Q 
M N 0 P 9 R 
N O ■ 

0 P 

Q S S f U V 
R S T U VW 
S T U V W X 
T U VW X V 
U VW X V Z 

V W X Y Z A 
W X^ Z A B 
X Y Z A B C 

Y Z A B C 0 
Z A B C D E 



N o p Q ^ a 
Q R 8 T 
R S T U 



O H I J 
H I J K 
I J K L 
J K LM 
K LM N 
LM N O 
M N O P 
N O P Q 
O P Q R 
P Q A 8 
g A 8 T 
A 8 T U 
8 T U V 
T U VW 
U VW X 
VW X Y 
W X Y 
X Y Z 
Y Z A 
Z A B 
ABC 
BCD 
C D E 
O E F O 
E F Q H 
F Q H I 



K LM N 
LM N 0 
M N 0 P 
N 0 P g 
0 P Q A 
P g R S 
b R 8 T 
R 8 T U 
8 T U V 
T U VW 
U VW X 
VW X V 
W X V Z 
X V Z A 
Y Z A B 
Z A B C 
A B C D 
B C D E 
e 0 E F 
D E F 0 
E F O H 
F O H I 
O H I J 
H I J K 
I J K L 
J K LM 



0 P g R 8 
P 6 R 8 T 
g A 8 T U 
R 8 T U V 
8 T U VW 
T U V W X 
U VW X Y 

V W X Y Z 
W X Y Z A 
X Y Z A B 

Y Z A B C 
Z A B C D 
A B C D E 
B C D E F 
C D E F Q 
D E F 0 H 
E F O H I 
F O H I J 

0 H I J K 
H I J K L 

1 J K LM 
J K LM N 
K LM N O 
LM N 0 P 
M N 0 P g 
N 0 P g R 



T U VW 
U V W X 

V W X Y 
W X Y 
X Y Z 

Y Z A 
Z A B 
ABC 
BCD 
C D E 
D E F 0 
E F 0 H 
F O H I 
OH I J 
H I J K 

I J K L 
J K LM 
K LM N 
LM N 0 
M N 0 P 
N 0 p.g 
0 P g R 
P g R 8 
g A 8 T 
A 8 T U 
8 T U V 



X 
Y 

z 

A 
B 

C 
D 

E F O 
F 0 H 
0 H I 
H I J 
I i K 
J K L 
K LM 
LM N 
M N 0 
NOP 
0 P g 
P g A 
g A 8 
AST 
8 T U 
T U V 
U VW 
VW X 
W X Y 



Fie. 4 .— The airaple \ntenire table. The cipher equivalent of a given 
plain-text letter enciphered by a given key letter ii that letter which itandi 
at the Intenection of the vertical column beaded by the former and the hori- 
zontal row begun by the latter. Thuz. plain-text letter E enciphered by key 
letter M yielde diiher letter Q, or, in brief notation, Ep(Mk) -Q>; Ep(Xk) “ 
B«, etc. 



Various modifications of the simple square table are encount- 
ered, these involving different types and arrangements of the 
sequences therein, but in every case where these sequences can 
be arranged so as to exhibit symmetry of position as regards the 
order in which the letters fall in the successive rows or columns, 
sliding or concentric primary sequences may be employed to pro- 
duce the same results as the table and are often more convenient. 

Polyalphabetic substitution systems may be classified as peri- 
odic or aperiodic, depending upon whether or not the cryptograms 
produced by them exhibit external phenomena of a cyclic nature. 
Periodicity is exhibited externally whenever the substitution 
process involves the use of keying elements which are used in a 
repetitive manner and which, in a single message, operate in con- 
junction with a fixed number of cipher alphabets, as would the 
example shown in fig. 5. 

Polyalphabetic systems of the aperiodic type are of great 
diversity in constniction. In these systems periodicity is either 
entirely lacking because of the nature of the method or it is sup- 
pressed by incorporating elements which serve as periodicity 
interrupters. In the well-known aperiodic system designated as 
the running-key or nonrepeating-key system, periodicity is avoided 
by employing for the key the xunaing text of a book, identical 
copies of which are in possession of the correspondents. The 
starting point of the keying sequence ia agreed upon in advance, 
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Ptein-text: 


L E T T E 
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E V H R X 


1 BMM P 


8 R K V 9 
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Fig. g. — An example of molUple alphabet •ubeUtutibn. The alphabeta of 
the limple \ngenire table (fig. 4) are uzed in eoniunction with the keyword 
TROY, which ia written above uie plain text and repeated aa many timea aa 
required. Each letter ia then enciphered by the keWetter above it. Thua, for 
the fint tetter, L*(Tk) wE«; for the aeoond letter, E^(Rk) ~Ve, etc. Uaually 
ail the plain-text letten governed by the fint letter of the key are endpbeted 
in auccemioa, theq thoae govented hy the aeoond, etc., thia method reducing 
the poaaibility of error. In practice, the keyword, and therefore the period, 
ia uaually longer than that employed in thia example, worda and phraaea of 
t5 to ao or more letten being common. Much nrore important, however, ia 
the fact that the alphaheta emjdoyed in modern timea are aeldom thoae of the 
aimple VlgenSre table, but are mixed alphabeta, the uae of which ttakea the 
cryptograma more aecure againat aolution. 



or is indicated in one of many ways by means of elements called 
indicators, which designate the exact point where the sequence 
begins. Another type of nonrepeating-key system, often desig- 
nated as the autokey system, is that in which, beginning with a 
preconcerted key letter, each cifdier letter (or sometimes each 
plain-text letter) becomes the key letter for the encipherment of 
the next plain-text letter. 

The various systems of substitution thus far mentioned are 
monographic in nature, involving single plain-text ‘ letters. In 
digraphic systems substitution is by pairs of letters and uses pre- 
agreed cii^er squares or matrices in which the letters of the 
alphabet are disposed according to some key and the cii^er equiv- 
alents of pairs of plain-text letters are found by following pre- 
arranged rules. One of the best-known systems of this sort is 
that called the Playfair cipher, named after Lyon, Baron Playfair, 
but invented by Sir Charles Wheatstone. It is illustrated in fig. 6. 

Properly selected methods of transposition and substitution 
when combined into a single system result in producing crypto- 
grams of great security, but because of the additional complex- 
ities of operation introduced by the combination, with the re- 
sultant increased possibilities of error, such systems are ndt often 
encountered in practice. 



I. Mcwge: AM FOLLOWINQ ON NEXT TRAIN, 

g. FUa-text; AMFOULOYnNOONNEXTTRAINX 
3 . apbcr: ORgFEIXOYXLBBXU EO AFHAU 

Cryfletram 

4. ORgFE ixavx LBBXL XEOAF HAU 

Fig. fi. — Ttw Playfair dpher; an examdc of digrapiiic aubatitutkm. Aa 
alphabet aquare of as lettera (I aetving alao aa J). baaed upon a keywotd (in 
thia caae "Lexiiigton") ia drawn up, and aubatitution ia poformed with pain 
of letten. Three caaee aa regarda the poaltion occupied In the aquare by the 
memben of a pair are poaaible; they lie (i) ia the eame horizontal row, or (a) 
in the aame veitical column, or (3) at the oppoaite enda of one of the diagonala 
of an imaginary rectangle. By atudylng the following exam pica under each 
caae the method of finding equivadenta wiUoecome apparent: Caae (i)LIwEN, 
AB-BG, OB-AG; Caae (z) ED -TP, EV-TE, W-VE; Caae (3) ER- 
IP, IM— LR, ST-PB. The text of the meaaage to be enciphered, uae i in 
the figure, ia divided up into pain, line a. Double-letter pain in the text are 
to be aeparated by an interpoaed letter auch aa X, aa ahown in the caae of the 
word "following in tide example. Note aleo the addiUon of the letter "X” 
to the end of the meaaage in order to make a pair of lettera. The cipher equiva- 
lenta are ahown in line 3. the final cryptogram in five-letter groupa, in line 4. 
Varloua airangementa of letten in the alphabet aquare are poaaibte, and com- 
pletely diaarranged alphabeta may be emirioyed. 
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Code Systems, — Basically, a code system is merely a type of 
substitution system in which the textu^ units that undergo cryp- 
tographic treatment are of varying and unequal lengths. Generally 
they are entire words, but often they may be single letters, syl- 
lables, numbers or phrases of varying length and sometimes whole 
sentences. The cryptoprinciple underlying code systems is very 
old and has as its essential element a specially compiled list of 
words, phrases and sentences, each of which is accompianied by a 
code group which may be another word (real or artificial) or 
a group of letters or figures. Identical copies of specialized lists 
of the foregoing sort, called codebooks or codes, are held by the 
communicators. In encoding a message it is necessary merely 
to refer to the codebook and replace the words, phrases or sen- 
tences composing the message by the code groups assigned them, 
constructing the code message, step by step, in this manner and 
using the fewest code groups possible. As to their cryptographic 
construction or arrangement of contents, codes may be of the one- 
part or the two-part type, the principal difierence between them 
being shosm in fig, 7. 
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The condensing power of a code obviously depends upon the 
extent and the nature of its vocabulapr The security of a code 
system depends somewhat upon the distribution and construction 
of the codebook, but mostly upon whether it is used in conjunc- 
tion with a good cipher system which is superimposed on the code 
text and the purpose of which is to afford secrecy, in the case of 
purchasable or publicly available codes, or additional secrecy, in 



One-pait Code 
A B A B A— A 

ABAC E — ^Abendon-lng-a 
A B A D 1 — ^Abandoned 
ABA FO— Abate-ing-« 
AB AO U— Abated 
A B AH V— Abeyance 
ABEBE— Abide-ins-e 
A B E C 1— Abided 

i V f V i— Zoiiew 


Two-pat 

BneodUtt 

KABOL— A 
S T 0 L Q — ^Abandon-ing-s 
EXIF 0 — ^Abandoned 
ZUMR A— Abated 
A B A B A — ^Abeyance 
R 0 A B V— Abide-ing-e 

B' ikliri— ZonM*‘ " 


tCode 

Dccodint 

A B A B A— Abeyance 
ABAC E — Procedure 
A B A D 1— To purehate 
A B A F 0— Commenced 
A B A Q U — Do not think 
A B AH V — Recorded 

Z V i V Z — Accor^ng to 


Fiflr. 7» ExtracU from typical one-part and two-part oodet. In the on^ 
part type the code groups and the vocabulary are arranged in paraltei, al- 
phabetic (or numerical) aequences, eo that a eingle book aervea for encoding at 
aa for decoding. In the two-p^ type the encoding book HaU the elementa 
of the vocabulary in alphabetic order but the code groups are in random order • 
ao that a decking txMk. in which the code groups appear in alphabetic (or 
numerical) order accomi^nied by their meanings, la essential. The demee of 
secrecy afforded by a code of the latter type Is much greater than that afforded 
by one of t^ former type, all other things being equal. 



the case of private or governmental codes. Code messages which 
undergo this second step are said to be superenciphered, re- 
encipthered or, simply, recip^ered. The principal purpose of code 
in commercial communications is to effect economy in their cost 
of electrical transmission, secrecy being usually of secondary im- 
portance (except in certain types of banking operations). Codes 
for gener^ business communications are purchasable from their 
publishers and therefore in themselves provide no secrecy. Many 
business firms, however, use specially compiled private codes 
which, if carefully restricted in distribution, may be regarded as 
confidential or secret. In governmental and especially in dip- 
lomatic or military communications secrecy is generally of ptimaiy 
importance, economy is secondary. 

Governmental codes which are intended to be secret are, of 
course, very carefully guarded in their production, distribution and 
usage and, as a general rule, messages in such codes are superen- 
ciphered. 

Cryptoapparatus^-^ryptodevices and cryptomachines vary 
in complexity from simple, superimposed, concentrically or eccen- 
trically rotating disks to large mechanical machines and electri- 
cally operated cryptoteleprinting apparatus. One of the best de- 
vices of the more simple, mechanical type is that known as the 
Bazeries cylinder (,see fig. 8), named after the French cryptog- 
rapher who is commonly credited with its invention in 1891. The 
principle upon which the device is based was, however, conceived 
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Fig. S. — ^THC GAZERIES CYLINDER 

Th* ButriM cylinder oontliti of ■ nt of 20 ditki, noh boorlng on Ite porlphory 
« difforontly inixod olphobot. Tho dliki, which boar Identifying nomben from 
1 to 20, are etiembled upon the theft In an order that oorretpondt to a nu- 
merloal key. To enolpher the fflotiage, 20 latteri are taken at a time, and the 
dliki are revolved to at to align the 20 lattart horliontallyi the latteri of any 
row can be taken for the olphar text. In daolpharing, the olphar lattan, taken 
20 at a time, ere aligned horliontally; the dlikt are than looked Into poiltlon. 
By llotvly revolving the whole oylinder and axamlning each row of letten, one 
and only one row will be found to yield Intelligible text all the way eoron 

many years before by Thomas Jefferson (see Jefferson’s Papers 
in the Library of Congress, vol. 232, item 41,575). 

Devices of the sort exemplified in fig. 8 soon proved to be in- 
adequate for modem cryptocommunications, as regards not only 
speed, accuracy and facility in operation but also security of the 
end product. It was not long, therefore, before more automatic 




Fig. P. — PORTABLE CRYPTODEVICE WHICH PRODUCES A PRINTED RECORD 
OF THE CIPHER TEXT AS WELL AS OF THE PLAIN TEXT. THE LETTERS TO 
BE ENCIPHERED OR DECIPHERED ARE SET BY TWIRLING’ THE INDICATING 
DISE SHOWN AT LEFT AND OPERATING THE LEVER AT THE RIGHT. THE SIX 
WHEELS CONTROL THE CRYPTOGRAPHY, IN CONJUNCTION WITH CERTAIN 
OTHER VARIABLE EEYING ELEHENTB INSIDE THE MACHINE 

and more secure types of apparatus were invented and developed. 
In such apparatus rotatory components referred to as cipher rotors 
have come to be of primary importance. The rotors may be of a 
mechanical or ah electrical type. Fig. 9 shows a machine which 
uses a series of mechanical rotors to produce an extremely long, 
continuously changing key for eneijAerment. Although the re- 
sults of manipulating the machine are printed upon a paper tape, 
the absence of a typewriter keyboard makes operation of the 
machine slow and t^ous. Fig, 10 shows a mach^e which uses a 
series of juxtaposed electrical rotors and stators to form a path 
for the passage of electric currents connecting the 26 keys of a 
keyboard to the 26 lamps of a light board upon which the results 
of manipulating the keys are indicated. Automatic angular dis- 
placements of the rotors serve to vary the path with each depres- 
sion of any key of the keyboard. From a practical point of view 
such a machine is not satisfactory for offices engaging extensively 
in cryptocommunication since it lacks an automatic recording or 




Fig. to. — ELECTRICAL CIPHER MACHINE EMPLOYING A TYPEWRITER KEY- 
BOARD 

printing mechanism and the results of operating the keyboard have 
to be recorded by the operator by hand. Therefore, a machine 
combining both a keyboard and a printing mechanism had to come, 
sooner or later. Such a combination of components is shown in 
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fig. II. Machines of this type, which are not necessarily associ- 
ated with the electrical communication system but which merely 
produce an end product (a printed record) that can be given to a 
communication centre or telegraph ofl&ce for transmission, are 
called off-Une cryptomachines. 

But even this stage in improvement in cryptocommunications 




Fig. II. — ^THE CRYPTOOEVICE OF FIG. 9 EQUIPPED WITH A KEYBOARD AND 
DRIVEN BY AN ELECTRIC MOTOR. THE TWO MACHINES ARE CRYPTOGRAPHI- 
CALLY INTERCOMMUNICABLE. THE OPERATING LEVER AT RIGHT IS USED 
IN CASK OF POWER FAILURE 

proved inadequate and communicators soon began to see need for 
on-line cryptomachines, i.e., apparatus which combines in a single 
and instantaneous operation the following steps: (i) manipulation 
of a key of the keyboard at the transmitting station to correspond 
to a character of the plain-text message; (2) automatic enci^er- 
ment of that character to form a cipher character; (3) electrical 
representation of that character by a signal or a permutation or 
combination of signals corresponding to the cipher character; (4) 
electrical transmission of the signal or signals; (5) their reception 
at the distant end; (6) their translation into a cipher character; 
(7) automatic decipherment of the character; and (8) printing 
the deciphered character — all this at the rate of at least 300 char- 
acters (=60 words) per minute. In fig. 12 is shown a prototype 
of such a machine. It is obvious, of course, that machines of tUs 
advanced type can be employed wily where there is direct access 
to transmission and reception facilities. 

As a result of extensive research and development after 1920, 
machines of the sorts here described have undergone considerable 
improvement, and further progress in written-cryptocommunica- 
tions technology appears to lie in this direction. 

Signal Intelligence. — ^The principal components of signal 
intelligence are: (i) communication intelligence, derived from 
the interception and analysis of signals which are involved in the 
exchange of messages or communications between piersons and 
which are, therefore, of the type designated as communication 
signals; and (2) electronic intelligence, derived from the inter- 
ception and analysis of electromagnetic radiations which are of 
a type other than those used in communications, such as radar, 
identification and recognition signals, navigational beacwis, etc., 
and which are therefore designated as noncommunication signals. 
It should be noted, however, that it is often difficult to draw a line 
of demarcation between communication intelligence and electronic 
inteUigence because these two fields deal with signals which merge 
into each other in the continuous spectrum generally referred to 
as that pertaining to communications electronics. 

Communication Intelligence,^ — This phase of cryptology 



deals with the processes, methods or means employed in deriving 
information by intercepting and analyzing enemy communications. 
Its principal components are: (i) interception and forwarding of 
traffic (messages) to analysis centres; (2) traffic analysis, includ- 
ing radio direction or position finding and operator identification ; 
and (3) cryptanalysis or solution (and translation, when neces- 
sary) of the texts of the messages. Only the last two components 
will be discussed. 

Traffic Analysis. — Stated in general terms, traffic analysis 
involves studying the messages exchanged within a communica- 
tions network for the purpose of penetrating the signal security 
camouflage superimpos^ thereon. 

Such study piermits reconstructing the networks from data such 
as volume, direction and routing of messages, frequencies, sched- 
ules and call signs used, etc. When the most important features 
of the networks have been thus ascertained, the analyst is not only 
able to ascertain the geografffiic locations and dispositions of mili- 
tary units (order of battle) and important movements of these 
units, but also to predict with varying degrees of reliability 
(based upon inferences) the area and extent of future military 
tactical or strategic operations. 

Cryptanalysis. — ^The science of solving cryptograpis by anal- 
ysis is called cryptanalysis, to distinguish the indirect methods 
of reading cryptograms from the direct methods which, of course, 
require a knowledge of the basic method and specific key, in the 
case of ciphers, or possession of the codebook, in the case of codes. 
Apart from the more simple, classical types, nearly every scien- 
tifically constructed cryptographic system presents a unique case 
in cryptanalysis, the unravelling of which requires the exercise 
of unusual powers of observation, inductive and deductive reason- 
ing, much concentration, perseverance and a vivid imagination; 
but all these qualities are of little avail without a special aptitude 
arising from extensive practical experience. It is worthwhile to 
note that the resistance which a specific cryptosystem wijl have 
against cryptanalysis is often vitally affected by the sophistication 
of the rules for its use and by the degree to which these rules are 
observed by cipher clerks. In respect to the latter, Francis Ba- 
con’s comment in his Of the Advancement of Learning (1605) is 
as true today as the day it was written: “But in regarde of the 
rawnesse and unskillfulnesse of the hands, through which they 
passe, the greatest Matters, are many times carryed in the weak- 
est cyphars.” 

A preliminary requisite to the analysis of a cryptogram is a 
determination of the language in which its plain text is written, 
information which is either already at hand in the case of official 
communications or which, in the case of private ones, can usually 
be obtained from extraneous circumstances. Next comes a de- 
termination as to whether a cipher or a code system is involved; 




Fig. 12. — A FRINTING TELEGRAPH CIPHER MACHINE 



this is based upon the fact that differences in their external ap- 
pearance are usually sufficiently well marked to be detectable. If 
the cryptogram is in cipher, the next step is to determine whether 
transposition or substitution is involved. This determination is 



5 



REF ID :A101014 

A -v Tf^ y-^TT-»r T1-< •¥-» ri 



made on the basis of the fact that in plain text the vowels and 
consonants are present in definite^ proportions. Since transposi- 
tion involves only a rearrangement of the original letters, it fol- 
lows that if a cryptogram contains vowels and consonants in the 
proportions normally found in plain text in the language in ques- 
tion, it is of the transposition class; if not, it is of the substitution 
class. The solution of trans[)osition ciphers involves much ex- 
perimentation with matrices of various types and dimensions, clues 
to which are afforded by the number of letters in the messages and 
extraneous circumstances. The assumption of the presence of 
probable words is often necessary. Special methods of solution 
based upon a study of messages of identical lengths, or with identi- 
cal beginnings or endings, are often possible to apply when much 
traffic has been intercepted. Finally, the presence of letters which 
individually are of low frequency but which when present have 
a great affinity for each other and form pairs of moderate or high 
frequency, such as qu in Spanish or ch in German, afford clues 
leading to solution. 

The basis upon which the solution of practically all substitution 
ciphers rests is the well-known fact that every written alphabetic 
language manifests a high degree of constancy in the relative 
frequencies with which its individual letters and combinations of 
letters are employed. For example, English telegraphic texts show 
the following relative frequencies in 1,000 letters, based upon an 
actual count of 100,000 letters appearing in a large but miscel- 
laneous assortment of telegrams of a commercial and governmen- 
tal nature, but all in plain language: 
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tifying the plain-text values of the cipher letters, but only when 
the cipher has been reduced to its simplest terms. Thus, the prob- 
lem of solving a monoalphabetic substitution cipher involves only 
one step, since the text is already in the simplest possible terms, 
and regardless of the kind of cipher alphabet employed practically 
every example of 25 or more characters representing the mono- 
alphabetic encipherment of a “sensible” message in English can 
readily be solved by the well-known principles of frequency, made 
popular by Edgar Allan Poe’s romantic tale The Gold Bug. How- 
ever, the problem of solving a polyalphabetic substitution cipher 
involves three principal steps: (i) determining the number of 
cipher alphabets involved; (2) distributing the cipher letters into 
the respective individual frequency tables to which they belong; 
aqd (5) analyzing each of the latter on the basis of normal fre- 
quencies in plain text of the language involved. In the case of 
aperiodic ciphers, because of the absence of cyclic phenomena, 
these steps are often very difficult, especially when the volume of 
text is limited. Frequently the only recourse is to employ repeti- 
tions as a ba^is for superimposing separate messages so that, ir- 
respective of the number of alphabets involved or their sequence, 
the letters pertaining to identical cipher alphabets fall into the 
same columns, and then the respective columns are treated as 
monoalphabetic frequency tables. The analysis of the frequency 
distributions of a polyalphabetic cipher is effected much more 
readily. when the alphabets are interrelated than when they are 
independent. 

The question as to whether an absolutely unsolvable cipher 
system can be devised is of more interest to laymen than to pro- 
fessional cryptographers. Edgar Allan Poe’s dictum that “it may 
be roundly asserted that human ingenuity cannot concoct a cipher 
which human ingenuity cannot resolve” is misleading unless qual- 
ified by restricting its application to the great majority of the 
practical systems employed for a voluminous, regular correspond- 
ence. Isolated short cryptograms prepared by certain methods 
may resist splution indefinitely; and a letter-for-letter cipher 
system which employs, once and only once, a keying sequence 
composed of characters or elements in a random and entirely un- 
predictable sequence may be considered holocryptic, that is, mes- 
sages in such a system cannot be read by indirect processes involv- 
ing cryptanalysis, but only by direct processes involving possession 



of the key or keys, obtained either legitimately, by virtue of being 
among the intended communicators, or by stealth. 

History, — ^It may as well be stated at the outset that as of the 
1950s there did not exist in any language a detailed, authentic and 
publicly available history of cryptology. Moreover, because of 
the curtain of secrecy which is invariably placed around crypto- 
logic work of an official character, accurate accounts of historically 
important events or of noteworthy inventions and improvements 
in cryptologic technology usually enter into the public domain 
only many years after the event or invention has occurred. 
Therefore, although it is difficult or impossible to ascertain with 
certainty much about the origin of any specific item or fact of 
cryptographic or cryptanalytic importance, the data should be 
traced back at least as far as the open or public records will 
permit. With this limitation in mind, this account will begin by 
noting that secret modes of signalling and communication have 
probably been in use from the earliest times, since the desire’ or 
need for secrecy in communication is certainly as old or nearly 
as old as the art of writing itself. However, mysteries such as 
the prophetic and apocalyptic writings of the orient and the say- 
ings of the Sibylline oracles are generally not regarded by cryptol- 
ogists as coming within their province; nor do they generally do 
anything more than merely refer to the various systems of stenog- 
raphy or shorthand used since the time of the Romans, including 
that known as Tironian notes, named after Tullius Tiro, Cicero’s 
learned freedman and friend, who elaborated a system which was 
popular for almost 1,000 years. Although it is valid to assume 
that cryptography was used by all of the peoples of antiquity, the 
assumption has been confirmed in the case of Egyptian hiero- 
glyphic writing by the outcome of studies which were begun by 
Jean Francois Champollion himself, were continued sporadically 
by other students for many years and culminated in 1932, disclos- 
ing that not one but three different sorts or degrees of cryptogra- 
phy were actually used by the ancient Egyptians. Cryptography 
was practised among the ancient Jews, whose Talmudic scholars 
dealt with it as a part or phase of their Kabbalah, which includes 
certain operations of a cryptographic nature. The ancient Greeks 
were users of the art, and at least one cryptographic device, called 
the scytale, is known to have been employed by the Lacedemonians 
for secret communications between military commanders in the 
field and their superiors at home. In the writings of Aeneas Tac- 
ticus (360-390 B.c.) is to be found the very earliest treatise on 
cryptography thus far discovered ; in addition to treating of secret 
dispatches, they contain a description of a cipher disk, a detailed 
explanation of which cannot here be included. Numerous ancient 
Greek documents exist which are either partially or wholly in 
cipher; and one cipher alphabet found therein has been traced 
back to the 9th century a.d. Despite the fact that Roman cryp- 
tographic documents are rather rare it is well known that the 
Romans used ciphers, for there are numerous references to those 
which Caesar and Augustus employed. In fact, the name Caesar 
is often used in cryptologic literature to designate the type of 
cipher alphabet and cipher system known as the monoalphabetic 
cipher using standard alphabets. In the middle ages (c. 450- 
1450) cryptography was employed rather infrequently, for the 
most part in connection with the pseudo sciences of alchemy and 
astrology. The most widespread cryptographic system of that 
period corresponds to that used by the Roman emperor Augustus, 
in which a letter was merely replaced by the one following it in 
the normal alphabet (but z was replaced by aa). Most often, 
however, only certain letters were thus replaced, sometimes only 
the vowels. 

The beginnings of modern cryptography can be traced back to 
Italy, the birthplace, as well, of modern diplomacy. Many cipher 
alphabets have come down to us which were used in the official 
messages of the papacy as well as in those of the early Italian 
republics. Ciphers were used in Venice as far back as in 1226; 
in Mantua and in Modena as early as 1305; and in Lucca, Flor- 
ence, Siena, Pisa and Milan before 1450. It was also in Italy, 
beginning soon after 1 500, that cryptologic operations first came to 
be organized on an effective basis. The invention of new cipher 
systems was promoted and reserves of cryptographic vocabularies 
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were prepared and kept in readiness for prompt issue as replace- 
ments for old or compromised ones. The earliest extant piece of 
work of a cryptographic nature is a small manual or compilation of 
the ciphers used about 1379 by Gabriel de Lavinde of Parma and 
preserved in the Vatican archives. In these ciphers all the letters 
were represented by arbitrary symbols and the vowels were 
treated no differently than the consonants in regard to the number 
of equivalents assigned them. However, some of these ciphers in- 
cluded nulls and others included brief lists of words and proper 
nouns, compilations first called nomenclators, then repertories 
and, later, small codes. By 1400 a.d. it had become apparent 
that each of the vowels should have more than a single cipher 
equivalent and there is a record of a cipher system involving a 
reversed standard alphabet with three different supplementary 
symbols as variants for each vowel. By the 15th century, ac- 
cording to Aloys Meister, Italian cryptography had been elab- 
orated to the point where “three to six different symbols could 
be used to represent a single letter of the alphabet, the indi- 
vidual syllables — arranged alphabetically for this purpose, ba, 
be, bi, bo, bu, ca, ce, ci, etc., — had specific cipher equivalents, 
and an ever-increasing number of complete words' were in- 
corporated into the nomenclators. Their abundance in content 
became so great that it was possible to fill a lengthy alphabetic 
index with the special equivalents for syllables and words . . .” 
The first complete cipher, i.e., one containing arbitrary sym- 
bols for each of the letters and variants for the vowels, as 
well as nulls and a nomenclator, is exemplified by a Venetian 
cipher of 1411, cited by Luigi Pasini. In the first half of the 15th 
century, after some further expansion in content, nomenclators 
attained such a state of development and practical utility that 
they remained for centuries the prototype of the diplomatic rep- 
ertories used by nearly all European governments, as well as by 
that of the young and rapidly growing republic in the western 
hemisphere, the United States. Before continuing with the ac- 
count of the further development of cryptosystems of this sort 
it may be well to direct attention to the invention and develop- 
ment of another cryptosystem which, originating in the very 
simple devices of the ancients, culminated some time during the 
1 6th century in the so-called chiffre indichiffrable (“the inde- 
cipherable cipher”) often referred to as the Vigen^re cipher (fig. 
4). It should be noted, however, that Vigenere’s description of 
the cipher differs decidedly from the form usually ascribed to 
him and presents an essentially more difficult problem to the 
cryptanalyst, that Vigenere nowhere speaks of the cipher as the 
chiffre indechiff cable par excellence, and that, except for an auto- 
keying principle, Vigenire lays no claim to having originated the 
cipher. 

Despite the much-advertised virtues and security of the Vi- 
genere cipher, practical cryptographers and cryptanalysts tended 
to put their faith rather in the older nomenclators and repertories, 
and it is therefore necessary to turn once more to these cryptoaids 
and follow their progress. 

The repertories used by France in the i6th century, under 
Louis XIII and Louis XIV, underwent important improvement 
with the introduction of an innovation which is now called the 
randomized or two-part arrangement of contents, illustrated in 
fig. 7. This improvement also soon found its way into the official 
cryptography of England and other countries. The repertories 
used by the papal court in the same century incorporated an ad- 
ditional new feature, that of making some or all of the cipher 
characters represent two or more different letters. After attaining 
this fairly advanced state of development, European cryptography 
went into a decline that reached its lowest level under Napoleon I; 
it is possible that one of the factors leading to the disaster which 
overtook him in Russia was the solution by the Russians of inter- 
cepted French ciphers. After the middle of the 19th century, 
stimulated perhaps by the spreading use of electromagnetic teleg- 
raphy, there came an expansion in the content of repertories, soon 
to be called codes. By the end of that century large codes con- 
taining 100,000 or more words and phrases were compiled not 
only for governmental but also for commercial communications. 
In suclr codes, of course, the length of the code equivalents had 



to be increased too, and code groups came to be composed, first, 
of groups of figures or of bona fide dictionary words, then of 
artificial words and, later, of five-letter groups constructed scien- 
tifically so as to obtain the maximum not only in economy in cost 
of transmission but also in efficiency in the correction of transmis- 
sion errors. For another 75 years, beginning about i860, the cryp- 
toprinciples embodied in tie early nomenclators but now expanded 
into large codes were the ones preferred for diplomatic and com- 
mercial cryptocommunications; literal or letter-for-letter ciphers 
were used only rarely for such communications. On the other 
hand, for military cryptocommunications, cipher systems of the 
latter type were preferred, except for high-level or strategic com- 
munications. In the U.S., during the War Between the States 
(1861-65), the Federal army employed small repertories in con- 
nection with word transposition, the so-called route cipher. The 
Confederate army used the Vigenere cipher — which the Federal 
army cryptanalysts are said to have solved every time a message 
in it was intercepted. 

During the first two years of World War I cipher systems were 
used almost to the exclusion of code systems by all belligerents 
for protecting tactical communications in. the field of operations, 
although code systems continued to be used for diplomatic and 
high-level strategic military cryptocommunications. By 1917, 
however, codes came to be used for the secret communications 
of the smaller and intermediate-size military formations. The 
extent of their vocabularies varied with the size of the unit; so 
that the code for communications between large units might con- 
tain 10,000 words and phrases, whereas that for communications 
between small units might contain only a few hundred or less. 
After about 1925 the direction of development and improvement 
in governmental cryptocommunications tended to explore and ex- 
ploit the possibilities of automatic cipher machines, as indicated 
earlier in this article, and this took place in all types of secret 
communications; diplomatic, military, naval, air, etc. This 
change in direction of evolution and development of cryptosys- 
tems, code systems giving way to cipher systems in practical cryp- 
tocommunications where secrecy is the primary consideration, is 
only an obvious result, in the field of communications, of the 
increased tempo of mechanization in all fields since the begin- 
ning of the 20th century. Cipher systems, the units of which 
are generally single letters, lend themselves much more readily 
to mechanization than do code systems, the units of which are 
generally complete words and often long phrases or sentences, 
because the number and lengths of different permutations and 
combinations of electrical signals needed to represent the rela- 
tively small number of different basic units of a written alphabetic 
language (in English 26 letters) are very much smaller than the 
number and lengths of different permutations and combinations 
that would be required to represent the large number of different 
words in such a language, not to mention phrases and sentences. 

This brief account of technological developments in cryptog- 
raphy has its counterpart in cryptanalysis, but if it is diflScult to 
ascertain with certainty data concerning the origin of any specific 
cryptosystem, because of the veil of secrecy already mentioned, 
it is almost impossible to ascertain with certainty by whom, where 
or when a specific cryptanalytic principle or process was first con- 
ceived or employed. The secrecy veil in this area becomes an 
almost impenetrable curtain, so that it is certainly valid to assume 
that news of cryptanalytic success or of the invention of a new 
technique becomes public only many years after the events or, 
pmrhaps, never. 

Under these circumstances, one hardly expects to find a his- 
torical account of the very first success in cryptanalysis, but the 
earliest brochure on record dealing with cryptanalytic theory is 
that of the Leone Battista Alberti, whose Trattati in cifra, written 
between 1467 and 1472, deals not only with cryptanalytic theories 
and processes but also with cryptography and statistical data. It 
is, therefore, the oldest treatise on cryptology in existence. The 
brief treatise of Sicco Simonetta, a cryptanalyst of the Sforzas at 
the court of Milan, which is dated July 4, 1474, and which is a 
strictly practical guide to cryptanalytic procedures, is the oldest 
treatise in the world purely devoted to cryptanalysis. Beginning 
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about 1506 and until 1539 another Italian professional cryptan- 
alyst, Giovanni Soro, devoted his leisure hours to the preparation 
of a treatise whicl)_has never been found. As was the case with 
cryptography, so on the cryptanalytic side the activities in the 
various small Italian republics and the papacy came to be organ- 
ized as serious enterprises. In order to protect these activities 
against indiscretions or “leakage,” the principles of secrecy and 
security were firmly established and wilful violations were treated 
as capital offenses. The development of technical skill was re- 
warded, and instruction in cryptanalysis was often carried on from 
one generation to the next in the same family. But, as in the 
cryptographic field, so in the cryptanalytic field there have been 
periods of progression and retrogression in technology. However, 
after about 1930 cryptanalytic technology progressed rather not- 
ably. The mechanization which afiected cryptography also af- 
fected cryptanalysis, and the invention and development or 
improvement of machines to aid in or speed up the tedious proc- 
esses usually involved in the solution of complex cryptosystems 
exercised an important effect upon the standards by which crypto- 
security had to be measured. 

The foregoing is a brief history of technological developments 
in cryptology. Nothing has yet been said about the usually very 
secret but quite important roles which poor cryptography or good 
cryptanalysis have played in international relations, both in peace 
and war, and in respect to both diplomatic and military affairs. 
As already stated, the historical accounts of these instances usu- 
ally lag many years behind the events to which they relate. But 



in at least one case in modem history the revelation of i^e spec-: 
tacular role played by cryptolq^ in diplomacy and warfare took 
place not very long after the event. Hearings held in Washington, 
D.C., 1945-46, by the joint committee on the investigation of 
the Pearl Harbor attack, made it clear that shortly before and 
during World War II U.S. cryptanalysts had considerable success 
in solving Japanese codes and ciphers, success indeed to the ex- 
tent that it was possible for the committee to state that all wit- 
nesses familiar with the intelligence produced “have testified that 
it contributed enormously to the defeat of the enemy, greatly 
shortened the war, and saved many thousands of lives.” For 
other instances the reader must consult some of the books listed 
in the bibliography, but not many will be found that pertain to 
relatively recent history. 

Bibliogkaphv. — Although no comprehensive and authentic history of 
cryptology had been published by the igsos, it is interesting to find 
that there does exist a comprehensive and scholarly bibliography of 
cryptologic literature covering practically all publicly available books 
and important papers on the subject: Joseph S. Galland, An Historical 
and Analytical Bibliography of the Literature of Cryptology (Evanston, 
111 ., 1945). Such a compilation is more helpful to specialists, than to 
the general reader, therefore, a selection of items from the Gailand 
bibliography may be useful. Also, after 1945 there were published a 
few items of importance which should be mentioned herein. Modern 
works worthy of special mention are as foliows; Andri Lange and E.-A. 
Soudart, Traiti de cryptographic (1925); Marcel Givierge, Cours de 
cryptographic (1925) ; Roger Baudouin, BUments de cryptographic 
(1939): H- F- Gaines, Elementary Cryptanalysis (Boston, iq.39; Lon- 
don, 1940); Luigi Sacco, Manuale de crittografia, 3rd ed. (1947); 
Charles Eyraud, Precis de cryptographic moderne (1953). (W. F. F.) 




8 



